projects
/
platform
/
upstream
/
nsjail.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
20745a4
)
keep_caps: make effective caps eq to permitted
author
Robert Swiecki
<robert@swiecki.net>
Mon, 23 Jan 2017 11:02:48 +0000
(12:02 +0100)
committer
Robert Swiecki
<robert@swiecki.net>
Mon, 23 Jan 2017 11:02:48 +0000
(12:02 +0100)
contain.c
patch
|
blob
|
history
diff --git
a/contain.c
b/contain.c
index 4b29e6ccc877fef306dd64a8d0235a3b10657595..1ab9e69ed14b95d71b648713af956cfa6c4dcbd1 100644
(file)
--- a/
contain.c
+++ b/
contain.c
@@
-112,6
+112,7
@@
static bool containDropPrivs(struct nsjconf_t *nsjconf)
if (nsjconf->keep_caps == true) {
for (size_t i = 0; i < _LINUX_CAPABILITY_U32S_3; i++) {
cap_data[i].inheritable = cap_data[i].permitted;
+ cap_data[i].effective = cap_data[i].permitted;
}
if (syscall(__NR_capset, &cap_hdr, &cap_data) == -1) {
PLOG_E("capset()");